PlayCISO · free tool
Malicious Skill Scanner
Vet an Agent Skill (a SKILL.md package) before you install it. It flags prompt-injection and “disable safety” directives in the instructions, and dangerous code — shell/eval, secret reads, exfiltration, reverse shells, persistence — in any bundled scripts, and grades it A–F.
Static-only — the scanner never executes the skill, so scanning a hostile skill can’t infect your host.
Why scanning can’t infect you
- • Never executes the skill — no eval/require/spawn, no running bundled scripts.
- • Content is data, not instructions — SKILL.md is pattern-matched as a string, and the AI intent pass reads it as nonce-delimited untrusted data it is told to analyse, never obey — so an injection payload inside it can’t hijack the scanner or the judge.
- • Never visits the skill’s URLs — a URL you supply is fetched text-only through an SSRF guard (no internal/metadata targets).
- • Detonation stays off-prod — real execution only ever runs on an isolated, disposable, network-isolated runner, never this host.